[GH-ISSUE #93] Security issue with attachment peaking #75

Closed
opened 2026-05-07 00:19:32 +02:00 by BreizhHardware · 0 comments

Originally created by @binwiederhier on GitHub (Jan 14, 2022).
Original GitHub issue: https://github.com/binwiederhier/ntfy/issues/93

With the attachment peaking feature for external URLs it was possible to probe localhost for open ports. I was not comfortable with leaving this in and it's tricky/impossible to isolate processes from the internal network, so I removed the feature.

The Android client will do the probing now.

Originally created by @binwiederhier on GitHub (Jan 14, 2022). Original GitHub issue: https://github.com/binwiederhier/ntfy/issues/93 With the attachment peaking feature for external URLs it was possible to probe localhost for open ports. I was not comfortable with leaving this in and it's tricky/impossible to isolate processes from the internal network, so I removed the feature. The Android client will do the probing now.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/ntfy#75
No description provided.